<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Configuring dot1x</title>
	<atom:link href="http://communitystring.com/2009/09/configuring-dot1x/feed/" rel="self" type="application/rss+xml" />
	<link>http://communitystring.com/2009/09/configuring-dot1x/</link>
	<description>My personal CCIE study notes for the Routing &#38; Switching track</description>
	<lastBuildDate>Tue, 06 Dec 2011 02:37:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Bradley</title>
		<link>http://communitystring.com/2009/09/configuring-dot1x/comment-page-1/#comment-24</link>
		<dc:creator>Bradley</dc:creator>
		<pubDate>Mon, 05 Oct 2009 09:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://communitystring.com/?p=350#comment-24</guid>
		<description>Hey Roland, many of the sites in our network have implemented dot1x for the wireless clients, its setup so they can travel to institutions throughout the world and still use the same credentials and is pretty successful www.eduroam.org

The biggest barrier we have found to deployment is sites understanding the technology, apart from the problem you described with changing VLANs the technology seems ready for prime time.</description>
		<content:encoded><![CDATA[<p>Hey Roland, many of the sites in our network have implemented dot1x for the wireless clients, its setup so they can travel to institutions throughout the world and still use the same credentials and is pretty successful <a href="http://www.eduroam.org" rel="nofollow">http://www.eduroam.org</a></p>
<p>The biggest barrier we have found to deployment is sites understanding the technology, apart from the problem you described with changing VLANs the technology seems ready for prime time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roland</title>
		<link>http://communitystring.com/2009/09/configuring-dot1x/comment-page-1/#comment-23</link>
		<dc:creator>Roland</dc:creator>
		<pubDate>Sat, 03 Oct 2009 21:27:53 +0000</pubDate>
		<guid isPermaLink="false">http://communitystring.com/?p=350#comment-23</guid>
		<description>802.1x is a great tool with a poor OS support. I&#039;m experiencing problems with WinXP clients and DHCP: the client gets an IP address from unauth VLAN and when the authentication completes it keeps the old ip address in the new vlan so a ipconfig /release and /renew is needed. I&#039;m using WinXP SP2 and SP3 with the same results. The client-side problems are a big issue in implementing 802.1x, I had to pause the whole project. Other dot1x clients fix that problem but it&#039;s hard to tell the customer to buy a new client and install it in &gt;1000 clients when EAP is supposed to be a OS feature free of charge. What&#039;s your experience?</description>
		<content:encoded><![CDATA[<p>802.1x is a great tool with a poor OS support. I&#8217;m experiencing problems with WinXP clients and DHCP: the client gets an IP address from unauth VLAN and when the authentication completes it keeps the old ip address in the new vlan so a ipconfig /release and /renew is needed. I&#8217;m using WinXP SP2 and SP3 with the same results. The client-side problems are a big issue in implementing 802.1x, I had to pause the whole project. Other dot1x clients fix that problem but it&#8217;s hard to tell the customer to buy a new client and install it in &gt;1000 clients when EAP is supposed to be a OS feature free of charge. What&#8217;s your experience?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: appelmoes</title>
		<link>http://communitystring.com/2009/09/configuring-dot1x/comment-page-1/#comment-22</link>
		<dc:creator>appelmoes</dc:creator>
		<pubDate>Fri, 25 Sep 2009 04:58:20 +0000</pubDate>
		<guid isPermaLink="false">http://communitystring.com/?p=350#comment-22</guid>
		<description>try

dot1x port-control auto

aaa authentication dot1x default group radius

and not

DistSwitch(config)#aaa authentication login default line</description>
		<content:encoded><![CDATA[<p>try</p>
<p>dot1x port-control auto</p>
<p>aaa authentication dot1x default group radius</p>
<p>and not</p>
<p>DistSwitch(config)#aaa authentication login default line</p>
]]></content:encoded>
	</item>
</channel>
</rss>

